What is a malicious signing request or wallet drainer?
Confirmed Published 7 min read
Short answer
A malicious signing request is a transaction someone tricks you into approving that sends your funds, or control of your account, to them; a wallet drainer is a scam built to deliver such requests. XRPL.org says a valid signature is the only authorization the XRP Ledger needs and no administrator can reverse an applied transaction, so the loss is final.
The full answer
How does a malicious signing request take your XRP?
On this page, a malicious signing request means a transaction someone else prepares and asks you to approve, which moves your funds or gives them power over your account. “Wallet drainer” is the common name for scams and tools built to deliver those requests.
The XRP Ledger does not check intent. XRPL.org’s cryptographic keys page, checked in September 2026, says digital signatures are the only way to authorize transactions, and that no privileged administrator can undo or reverse a transaction after it has applied [1]. The same page says anyone who knows an account’s seed or private key can sign any transaction the owner could [1]. Reading those two rules together, a drainer that gets one valid signature from the owner ends up with the same result as one that stole the key.
Other authorities say the same about reversal. The FBI’s Internet Crime Complaint Center (IC3) says crypto transactions are irrevocable and that no third party sits between them or authorizes them [2]. The US Federal Trade Commission says crypto payments typically are not reversible, and that money usually comes back only if the person you paid sends it back [3]. Ripple says on its scam-awareness page that it cannot stop or alter transactions on the XRP Ledger [4].
Which XRP Ledger transaction types can hand over account control, such as SetRegularKey?
A payment that empties the balance is the obvious risk. Account settings can do quieter damage.
XRPL.org says a regular key pair can be removed or replaced at any time, and that a regular key or multi-signature can do anything else the master key pair can [1]. Its multi-signing page says the SignerListSet transaction defines a signer list, a set of addresses that can authorize transactions from your address [5]. That page also gives an example in which friends on a signer list multi-sign a transaction to replace an owner’s lost regular key [5].
Taken together, a sign request that sets a regular key or a signer list chosen by someone else would hand that person signing power over the account. No XRP would need to leave at the moment of approval, so the balance could look normal right afterwards. That is an inference from XRPL.org’s documentation, set out in the analysis list on this page.
The fee field is another quiet route. XRPL.org says every transaction destroys the exact amount of XRP written in its Fee field, even when that is much more than the current minimum [6]. The minimum for a standard transaction is 10 drops [6], and one drop is 0.000001 XRP [7].
How do I read an XRP Ledger sign request before approving it?
The fields below follow from the rules above. Each one is something a request can be used to change.
- Transaction type. A payment moves value. A regular key or SignerListSet transaction changes who can sign for the account [1][5].
- Destination address. The FBI’s Denver field office warned on April 26, 2024 that look-alike addresses can share the first and last characters of a familiar address while the middle differs, and advised checking the entire address [8].
- Destination tag. XRPL.org says a payment to an exchange can use a destination tag to show which customer to credit [9].
- Fee. Compare the Fee against the 10-drop minimum for a standard transaction [6].
The setting matters as much as the fields. The FBI’s April 6, 2026 release on crypto and AI scams told people to resist pressure to act quickly and to assess the situation before turning over money [10]. D’CENT says in its app FAQ that, on its hardware wallet, every transfer must be approved on the device and the phone app serves only as the interface for display and operation [11]. On that model, the device screen is the place to read a request, because the app or website that produced it may be the part an attacker controls.
Where do drainer requests come from?
Chainalysis said major scam operations became increasingly industrialized in 2025, using phishing-as-a-service tools, AI-generated deepfakes and professional money laundering networks [12].
Unexpected tokens are one entry point. Ripple lists unfamiliar crypto assets or tokens appearing in your wallet among its scam warning signs [4]. The FBI’s IC3 said on June 3, 2025 that when unsolicited airdrop tokens arrive in a non-custodial wallet, a plaintext memo can appear alongside them [13]. The page on strange tokens, airdrops and messages in an XRP wallet covers what those memos ask people to do. Look-alike addresses are a related trick, covered in the page on address poisoning.
Does a hardware wallet or air-gapped signing stop it?
A hardware wallet changes where the key lives. D’CENT says the private key on its hardware wallet stays within the device’s secure chip [11]. XRPL.org’s secure signing page says any setup in which outside sources may gain access to your secret key is dangerous and likely to end with a malicious user stealing all your XRP [14].
The limits are documented too. FINRA says hardware wallets aren’t totally immune from sophisticated hacking techniques [15]. D’CENT says that if a hardware wallet’s recovery phrase was ever entered into an app wallet or any other software wallet, the two share the same private keys and the hardware wallet should not be treated as isolated [11].
Not every drain needs a sign request at all. XRPL.org reported on April 28, 2025 that versions of the xrpl.js library published on April 21, 2025 carried malicious code built to capture secret key material and send it to an attacker’s website [16]. Reading the evidence together, offline keys and on-device approval block that key-theft route, but they cannot stop an owner from approving a harmful transaction the device displays correctly. The page on air-gapped signing sets out what fully offline signing adds, and the strongest critique of trusting devices is on the page asking whether a hardware wallet can be hacked.
I approved something suspicious; what do I do right now?
Start by finding out what was signed. The page on reading an XRP Ledger transaction on a public explorer shows where to look up the transaction type, destination and fee.
If the secret itself may be exposed, XRPL.org’s guidance after the xrpl.js incident was blunt: anyone who installed the infected versions should assume their wallets were compromised and follow its key rotation recommendations [16]. XRPL.org also says to disable the master key pair if it may have been compromised, after checking that a regular key or multi-signing list works [17]. The ledger refuses a transaction that tries to remove the only remaining way of authorizing transactions, with the result code tecNO_ALTERNATIVE_KEY [18]. XRPL.org warns that no one can restore access to an account if something goes wrong [17].
If the request changed who can sign, XRPL.org says a regular key can be removed or replaced at any time, and that a master key kept enabled but offline can still be found and used in an emergency [1]. Whether that helps depends on who now holds working keys, which is why the first step is reading the transaction.
Report it, even if nothing has moved yet. The FBI’s IC3 asks for complaints even where no financial loss occurred, with the crypto addresses, amounts and types, transaction hashes, and dates and times [2]. In Canada, the Anti-Fraud Centre’s victim page says to gather all information including emails and texts, report to the financial institution that transferred the money, get a police file number, and report to the centre online or at 1-888-495-8501 [19]. Ripple’s reporting steps include telling your exchange, custodian or wallet provider [4]. The page on reporting an XRP scam has the full list.
Expect a second approach. The Canadian Anti-Fraud Centre says fraudsters often target victims a second or third time with the promise of recovering money, and tells people never to send recovery money [19]. The FBI’s IC3 said on June 24, 2024 that anyone who contacts you claiming they can recover stolen crypto should get no money and no personal information, and that law enforcement does not charge victims a fee [20]. The page on crypto recovery scams covers how these offers work.
How common are drainers on the XRP Ledger?
No count exists for this ledger alone. As of October 1, 2026, no government agency or security firm had published a figure for wallet-drainer losses on the XRP Ledger specifically. Chainalysis estimated that about $17 billion was stolen in crypto scams and fraud in 2025 [12], a total for scams and fraud in general rather than for drainers.
What we know
- XRPL.org’s cryptographic keys page (checked September 29, 2026) says digital signatures are the only way to authorize XRP Ledger transactions, that no privileged administrator can undo or reverse a transaction after it has applied, and that anyone who knows an account’s seed or private key can sign any transaction the owner could.
- The same XRPL.org page (checked September 29, 2026) says a regular key pair can be removed or replaced at any time, and that a regular key or multi-signature can do anything else the master key pair can.
- XRPL.org’s multi-signing page (checked September 2026) says the SignerListSet transaction defines a signer list, a set of addresses that can authorize transactions from your address.
- XRPL.org’s transaction cost page (checked September 29, 2026) says every transaction destroys the exact amount of XRP in its Fee field, even when that is far above the current minimum of 10 drops for a standard transaction.
- The FBI’s Internet Crime Complaint Center (page checked September 29, 2026) says crypto transactions are irrevocable, and the FTC (page checked September 29, 2026) says crypto payments typically are not reversible.
- Ripple says on its scam-awareness page (checked September 29, 2026) that it cannot stop or alter transactions on the XRP Ledger, and lists unfamiliar tokens appearing in a wallet as a warning sign.
- The FBI’s Denver field office warned on April 26, 2024 that look-alike addresses can share the first and last characters of a familiar address, and advised checking the entire address.
- Chainalysis said major scam operations became increasingly industrialized in 2025, using phishing-as-a-service tools, AI-generated deepfakes and professional money laundering networks.
- XRPL.org reported on April 28, 2025 that xrpl.js versions published on April 21, 2025 carried malicious code built to capture secret key material.
What we reason Analysis
- A sign request that sets a regular key or a signer list chosen by someone else would give that person signing power over the account without moving any XRP at the moment of approval. XRPL.org’s cryptographic keys page says a regular key can do anything else the master key can, and its multi-signing page says a signer list sets the addresses that can authorize transactions.
- Because a drained account was validly signed by its owner, there is no ledger-level route to undo it; getting funds back depends on the receiver, which matches what XRPL.org, the FBI’s IC3, the FTC and Ripple each say about reversal.
- Approving transactions on a hardware device protects the private key, but it cannot judge whether the transaction itself is harmful. D’CENT’s FAQ says the key stays in the device’s chip and every transfer is approved on the device, and XRPL.org’s documentation says a valid signature is all the ledger checks.
- An inflated Fee field is a way to lose XRP without any visible payment to another address. XRPL.org’s transaction cost page says the Fee amount is destroyed in full even when it is much more than the minimum.
- A holder who still controls the master key can, in principle, replace or remove a regular key someone else installed. This rests on XRPL.org’s statements that a regular key can be replaced or removed at any time and that a master key kept enabled but offline can be used in an emergency.
What's still open
- As of October 1, 2026, no government agency or security firm had published a count of wallet-drainer losses on the XRP Ledger specifically.
- As of October 1, 2026, no independent public comparison had been published of how XRP Ledger wallets display each transaction type, such as regular key or signer list changes, before the user signs.
In plain English
When you hold crypto in your own wallet, approving a transaction works like signing a cheque that can never be cancelled. A scammer can dress up a harmful transaction as something routine and ask you to approve it. On the XRP Ledger nobody can undo it afterwards, and some approvals could hand over control of the account instead of moving money straight away. The steps covered here are reading what you approve, checking the whole address, and reporting quickly if something goes wrong.
Key terms
Sources
- Cryptographic Keys — XRPL.org, Undated, checked September 29, 2026 Primary
- Cryptocurrency — FBI Internet Crime Complaint Center (IC3), Undated, checked September 29, 2026 Primary
- What To Know About Cryptocurrency and Scams — US Federal Trade Commission, Undated, checked September 29, 2026 Primary
- How to identify crypto scams — Ripple, Undated, checked September 29, 2026 Company-reported
- Multi-Signing — XRPL.org, Undated, checked September 2026 Primary
- Transaction Cost — XRPL.org, Undated, checked September 29, 2026 Primary
- Currency Formats — XRPL.org, Undated, checked September 29, 2026 Primary
- FBI Warns of Cryptocurrency Token Impersonation Scam — FBI Denver, April 26, 2024 Primary
- Source and Destination Tags — XRPL.org, Undated, checked September 2026 Primary
- Cryptocurrency and AI Scams Bilk Americans of Billions — FBI, April 6, 2026 Primary
- FAQ: DCENT App — D'CENT (IoTrust), September 2026 Company-reported
- Crypto Scams 2026 — Chainalysis, January 13, 2026 Company-reported
- Public Service Announcement on cryptocurrency airdrops and memos — FBI Internet Crime Complaint Center (IC3), June 3, 2025 Primary
- Secure Signing — XRPL.org, Undated, checked September 2026 Primary
- Crypto Storage — FINRA, Undated, checked September 2026 Primary
- Vulnerability Disclosure Report: xrpl.js, April 2025 — XRPL.org, April 28, 2025 Primary
- Disable Master Key Pair — XRPL.org, Undated, checked September 29, 2026 Primary
- tec Codes — XRPL.org, Undated, checked September 29, 2026 Primary
- Victim of fraud — Canadian Anti-Fraud Centre, January 16, 2026 Primary
- Fictitious Law Firms Targeting Cryptocurrency Scam Victims — FBI Internet Crime Complaint Center (IC3), June 24, 2024 Primary
- XRPL Payment Drain Tracker — XRPL.to, read 2026-10-02 Primary
- XRP Healthcare Shuts Down: How a Wallet-App Flaw Drained 4,011 XRP Wallets — Yahoo Finance (originally 99bitcoins.com), September 11, 2026 Secondary
- XRP Ledger News | TokenPost — TokenPost, read 2026-10-02 Secondary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
